I deleted Bbuloa.exe from the WINDOWS two days ago before you told me to run any scans and everything seems back to normal.
Here are the scan results that you requested.
Gmer:
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-06-12 13:41:57
Windows 5.1.2600 Service Pack 2
Running: 9bh453fi.exe; Driver: C:\DOCUME~1\818\LOCALS~1\Temp\uxqoqaob.sys
—- System - GMER 1.0.15 —-
SSDT F7BFAD26 ZwCreateKey
SSDT F7BFAD1C ZwCreateThread
SSDT F7BFAD2B ZwDeleteKey
SSDT F7BFAD35 ZwDeleteValueKey
SSDT F7BFAD3A ZwLoadKey
SSDT F7BFAD08 ZwOpenProcess
SSDT F7BFAD0D ZwOpenThread
SSDT F7BFAD44 ZwReplaceKey
SSDT F7BFAD3F ZwRestoreKey
SSDT F7BFAD30 ZwSetValueKey
SSDT F7BFAD17 ZwTerminateProcess
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip FILTNT.SYS (Virtual Firewall driver/Agnitum)
AttachedDevice \Driver\Tcpip \Device\Tcp FILTNT.SYS (Virtual Firewall driver/Agnitum)
AttachedDevice \Driver\Tcpip \Device\Udp FILTNT.SYS (Virtual Firewall driver/Agnitum)
AttachedDevice \Driver\Tcpip \Device\RawIp FILTNT.SYS (Virtual Firewall driver/Agnitum)
—- EOF - GMER 1.0.15 —-
OTL:
OTL logfile created on: 6/13/2010 11:32:26 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\818\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
478.00 Mb Total Physical Memory | 228.00 Mb Available Physical Memory | 48.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 49.12 Gb Free Space | 65.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-TH3IEUQTQB
Current User Name: 818
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\818\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\system32\ZDWLAN.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe (COMPAL ELECTRONIC INC.)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe (Agnitum)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\818\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe ()
SRV - (wampapache) – c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe (Apache Software Foundation)
SRV - (CeEPwrSvc) – C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe (COMPAL ELECTRONIC INC.)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
SRV - (OutpostFirewall) – C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe (Agnitum)
========== Driver Services (SafeList) ==========
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (truecrypt) – C:\WINDOWS\system32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (ZD1211U(ZyDAS)) WLAN 802.11g USB2.0 Adapter(ZyDAS) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (RT2500) – C:\WINDOWS\system32\drivers\RT2500.sys (Ralink Technology Inc.)
DRV - (ZDPNDIS5) – C:\WINDOWS\system32\ZDPNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (EPOWER) – C:\WINDOWS\system32\drivers\hkdrv.sys (Compal Electronic Inc.)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - ({E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}) – C:\WINDOWS\system32\drivers\wA301a.sys (Intel Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (SrvcSSIOMngr) – C:\WINDOWS\system32\drivers\SSIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEPIOMngr) – C:\WINDOWS\system32\drivers\EPIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEKIOMngr) – C:\WINDOWS\system32\drivers\EKIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (wlluc48) – C:\WINDOWS\system32\drivers\wlluc48.sys (Lucent Technologies)
DRV - (SrvcTPIOMngr) – C:\WINDOWS\system32\drivers\TPIOMngr.sys ()
DRV - (wlags48b) – C:\WINDOWS\system32\drivers\wlags48b.sys (Agere Systems)
DRV - (PROTECT.DLL) Outpost Firewall PlugIn (PROTECT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Protect.dll (Agnitum)
DRV - (FTPFILT.DLL) Outpost Firewall PlugIn (FTPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Ftpfilt.dll (Agnitum)
DRV - (IMAPFILT.DLL) Outpost Firewall PlugIn (IMAPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Imapfilt.dll (Agnitum)
DRV - (NNTPFILT.DLL) Outpost Firewall PlugIn (NNTPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Nntpfilt.dll (Agnitum)
DRV - (CONTENT.DLL) Outpost Firewall PlugIn (CONTENT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Content.dll (Agnitum)
DRV - (MAILFILT.DLL) Outpost Firewall PlugIn (MAILFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Mailfilt.dll (Agnitum)
DRV - (POP3FILT.DLL) Outpost Firewall PlugIn (POP3FILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Pop3filt.dll (Agnitum)
DRV - (ADBLOCK.DLL) Outpost Firewall PlugIn (ADBLOCK.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\ADBLOCK.dll (Agnitum)
DRV - (HTMLFILT.DLL) Outpost Firewall PlugIn (HTMLFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Htmlfilt.dll (Agnitum)
DRV - (HTTPFILT.DLL) Outpost Firewall PlugIn (HTTPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Httpfilt.dll (Agnitum)
DRV - (DNSCACHE.DLL) Outpost Firewall PlugIn (DNSCACHE.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Dnscache.dll (Agnitum)
DRV - (VFILT) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\2000\Filtnt.sys (Agnitum)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
DRV - (TBiosDrv) – C:\WINDOWS\system32\drivers\Tbiosdrv.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "
http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "
http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.1
FF - prefs.js..extensions.enabledItems: orbit_ffext@orbitdownloader:2.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.http: "209.191.82.40"
FF - prefs.js..network.proxy.http_port: 80
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/12/30 18:15:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/05/31 19:25:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/04 20:45:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/02 12:23:50 | 000,000,000 | —D | M]
[2009/04/06 18:26:55 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Extensions
[2010/06/11 16:27:32 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions
[2008/03/13 14:34:44 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\{1650a312-02bc-40ee-977e-83f158701739}(2)
[2010/04/27 20:14:36 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/01/29 11:42:02 | 000,000,000 | —D | M] (Adblock) – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2009/04/06 18:26:56 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\[removed]
[2009/04/05 15:06:07 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\[removed](2).org
[2008/03/12 22:33:52 | 000,002,386 | —- | M] () – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\searchplugins\siteadvisor.xml
[2010/06/11 16:27:32 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/02 12:23:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2007/12/30 18:15:25 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/05/02 12:23:08 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2008/07/19 18:03:42 | 000,240,768 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 babe.the-killer.bz
O1 - Hosts: 127.0.0.1 www.babe.the-killer.bz
O1 - Hosts: 127.0.0.1 babe.k-lined.com
O1 - Hosts: 127.0.0.1 www.babe.k-lined.com
O1 - Hosts: 127.0.0.1 did.i-used.cc
O1 - Hosts: 127.0.0.1 www.did.i-used.cc
O1 - Hosts: 127.0.0.1 coolwwwsearch.com
O1 - Hosts: 127.0.0.1 www.coolwwwsearch.com
O1 - Hosts: 127.0.0.1 coolwebsearch.com
O1 - Hosts: 127.0.0.1 www.coolwebsearch.com
O1 - Hosts: 127.0.0.1 hi.studioaperto.net
O1 - Hosts: 127.0.0.1 www.hi.studioaperto.net
O1 - Hosts: 127.0.0.1 webbrowser.tv
O1 - Hosts: 127.0.0.1 www.webbrowser.tv
O1 - Hosts: 127.0.0.1 wazzupnet.com
O1 - Hosts: 127.0.0.1 www.wazzupnet.com
O1 - Hosts: 127.0.0.1 gueb.com
O1 - Hosts: 127.0.0.1 www.gueb.com
O1 - Hosts: 127.0.0.1 kabex.com
O1 - Hosts: 127.0.0.1 www.kabex.com
O1 - Hosts: 127.0.0.1 hityou.com
O1 - Hosts: 127.0.0.1 www.hityou.com
O1 - Hosts: 127.0.0.1 miosearch.com
O1 - Hosts: 127.0.0.1 www.miosearch.com
O1 - Hosts: 8421 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (no name) - {B6FF8C4D-6FAF-3B2F-DC5F-3AE671F70C97} - C:\WINDOWS\System32\ckvnz.dll File not found
O2 - BHO: (no name) - {e9acaeed-f5e5-40ed-bc1a-7ecd39c46ef9} - C:\WINDOWS\System32\olmqewdh.dll File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe File not found
O4 - HKLM..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe File not found
O4 - HKLM..\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe File not found
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe File not found
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe File not found
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe File not found
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe File not found
O4 - HKLM..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe (Agnitum)
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe File not found
O4 - HKLM..\Run: [ZDWLAN.EXE] C:\WINDOWS\System32\ZDWLAN.exe ()
O4 - HKCU..\Run: [M5T8QL3YW3] C:\DOCUME~1\818\LOCALS~1\Temp\Bjw.exe File not found
O4 - HKCU..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe File not found
O4 - Startup: C:\Documents and Settings\818\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-0000-0000-000000000000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\pmnmmli: DllName - pmnmmli.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\818\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\818\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/08/27 13:43:38 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2003/08/27 13:43:00 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/06/10 23:56:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MainType
[2010/06/10 21:05:30 | 000,000,000 | —D | C] – C:\cygwin2
[2010/06/10 17:08:32 | 000,000,000 | —D | C] – C:\cygwin
[2010/06/10 00:18:40 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\Proxima Software
[2010/06/10 00:18:40 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\Obsidium
[2010/06/09 21:42:35 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\FontCreator
[2010/06/07 18:27:05 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Desktop\rks_trial002a
[2010/05/22 22:06:54 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Local Settings\Application Data\Temp
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/06/13 10:37:43 | 000,039,847 | —- | M] () – C:\Documents and Settings\818\Desktop\game_sprite_classes.py
[2010/06/13 02:11:06 | 000,000,970 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005UA.job
[2010/06/13 02:11:00 | 000,000,274 | -H– | M] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/06/13 01:58:00 | 000,000,242 | -H– | M] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/06/13 00:34:28 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/13 00:34:07 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/12 22:30:06 | 007,340,032 | —- | M] () – C:\Documents and Settings\818\ntuser.dat
[2010/06/12 22:29:40 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\818\ntuser.ini
[2010/06/12 22:29:20 | 001,575,706 | -H– | M] () – C:\Documents and Settings\818\Local Settings\Application Data\IconCache.db
[2010/06/12 22:11:01 | 000,000,918 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005Core.job
[2010/06/12 20:54:30 | 000,045,446 | —- | M] () – C:\Documents and Settings\818\Desktop\sprite_class.py
[2010/06/12 18:38:20 | 000,028,640 | —- | M] () – C:\Documents and Settings\818\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/12 18:31:27 | 014,957,056 | —- | M] () – C:\Documents and Settings\818\My Documents\Dorian GrayB.ppt
[2010/06/12 18:30:49 | 014,957,056 | —- | M] () – C:\Documents and Settings\818\My Documents\Dorian Gray.ppt
[2010/06/12 12:55:26 | 062,861,312 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/06/12 11:02:48 | 000,129,296 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 00:16:33 | 000,054,975 | —- | M] () – C:\Documents and Settings\818\Desktop\server.py
[2010/06/11 18:32:55 | 000,000,791 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/11 17:56:29 | 000,089,088 | —- | M] () – C:\Documents and Settings\818\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/11 17:48:03 | 000,000,514 | —- | M] () – C:\Documents and Settings\818\Application Data\turing_files.ini
[2010/06/11 00:35:02 | 000,000,151 | —- | M] () – C:\WINDOWS\fcp5.cfg
[2010/06/10 21:46:45 | 000,000,154 | —- | M] () – C:\WINDOWS\mt3.cfg
[2010/06/10 00:18:40 | 000,001,026 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/09 18:39:55 | 000,020,309 | —- | M] () – C:\Documents and Settings\818\Desktop\game_attack_classes.py
[2010/06/09 18:37:59 | 000,012,255 | —- | M] () – C:\Documents and Settings\818\Desktop\game_sprite_classes.pyc
[2010/06/09 18:32:35 | 000,019,313 | —- | M] () – C:\Documents and Settings\818\Desktop\sprite_class.pyc
[2010/06/08 17:16:31 | 000,002,279 | —- | M] () – C:\Documents and Settings\818\Desktop\Google Chrome.lnk
[2010/06/08 16:42:08 | 000,007,563 | —- | M] () – C:\Documents and Settings\818\Desktop\game_attack_classes.pyc
[2010/06/08 16:17:01 | 000,003,914 | —- | M] () – C:\Documents and Settings\818\Desktop\game_maps.pyc
[2010/06/07 23:30:50 | 000,005,292 | —- | M] () – C:\Documents and Settings\818\Desktop\game_maps.py
[2010/06/07 00:29:25 | 000,303,685 | —- | M] () – C:\Documents and Settings\818\Desktop\realistic_rpg_icons_spells.jpg
[2010/06/04 21:01:12 | 000,046,765 | —- | M] () – C:\Documents and Settings\818\Desktop\server_back.py
[2010/05/30 13:09:39 | 023,769,026 | —- | M] () – C:\Documents and Settings\818\Desktop\absurd64.zip
[2010/05/27 21:51:20 | 000,027,136 | —- | M] () – C:\Documents and Settings\818\My Documents\Poem Analysis.doc
[2010/05/27 21:00:42 | 000,022,528 | —- | M] () – C:\Documents and Settings\818\My Documents\The Children are Laughing.doc
[2010/05/27 17:53:17 | 000,139,264 | —- | M] () – C:\Documents and Settings\818\My Documents\Repetition.ppt
[2010/05/26 21:15:26 | 000,033,792 | —- | M] () – C:\Documents and Settings\818\My Documents\The Picture of Dorian Gray.doc
[2010/05/23 10:24:49 | 000,040,441 | —- | M] () – C:\Documents and Settings\818\My Documents\mystic_fighters_logo.png
[2010/05/18 21:25:45 | 000,001,634 | —- | M] () – C:\Documents and Settings\818\Desktop\config.py
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/06/12 18:31:24 | 014,957,056 | —- | C] () – C:\Documents and Settings\818\My Documents\Dorian GrayB.ppt
[2010/06/12 12:50:27 | 014,957,056 | —- | C] () – C:\Documents and Settings\818\My Documents\Dorian Gray.ppt
[2010/06/11 18:32:54 | 000,000,791 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/10 23:42:14 | 000,000,274 | -H– | C] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/06/10 23:42:12 | 000,000,242 | -H– | C] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/06/10 21:46:45 | 000,000,154 | —- | C] () – C:\WINDOWS\mt3.cfg
[2010/06/09 21:43:00 | 000,000,151 | —- | C] () – C:\WINDOWS\fcp5.cfg
[2010/06/07 00:29:23 | 000,303,685 | —- | C] () – C:\Documents and Settings\818\Desktop\realistic_rpg_icons_spells.jpg
[2010/05/27 17:45:49 | 000,139,264 | —- | C] () – C:\Documents and Settings\818\My Documents\Repetition.ppt
[2010/05/26 21:32:01 | 000,022,528 | —- | C] () – C:\Documents and Settings\818\My Documents\The Children are Laughing.doc
[2010/05/24 12:53:01 | 000,027,136 | —- | C] () – C:\Documents and Settings\818\My Documents\Poem Analysis.doc
[2010/05/23 10:24:47 | 000,040,441 | —- | C] () – C:\Documents and Settings\818\My Documents\mystic_fighters_logo.png
[2010/05/22 22:08:17 | 000,002,279 | —- | C] () – C:\Documents and Settings\818\Desktop\Google Chrome.lnk
[2010/05/22 22:06:52 | 000,000,970 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005UA.job
[2010/05/22 22:06:51 | 000,000,918 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005Core.job
[2010/05/18 21:15:52 | 000,001,634 | —- | C] () – C:\Documents and Settings\818\Desktop\config.py
[2009/06/01 21:16:05 | 000,000,031 | —- | C] () – C:\WINDOWS\Caligari.ini
[2009/05/14 22:23:40 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS74.DLL
[2008/05/19 14:12:46 | 000,000,051 | —- | C] () – C:\WINDOWS\GunzLauncher.INI
[2008/04/29 20:58:46 | 000,041,296 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2007/12/31 13:22:28 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2007/12/30 12:55:53 | 000,000,294 | -HS- | C] () – C:\WINDOWS\System32\bcdnfblg.ini
[2007/12/23 14:48:05 | 000,000,096 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/03/05 13:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/02/16 18:53:57 | 000,001,066 | —- | C] () – C:\WINDOWS\pae.ini
[2007/02/03 11:59:04 | 000,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/01/05 15:17:01 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2007/01/05 15:17:01 | 000,000,149 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2006/09/16 15:30:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/07/19 16:31:57 | 000,000,000 | —- | C] () – C:\WINDOWS\CeEKey.INI
[2006/07/16 12:56:28 | 000,001,135 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/07/12 14:18:29 | 000,006,528 | —- | C] () – C:\WINDOWS\System32\drivers\Tbiosdrv.sys
[2006/07/12 14:18:13 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2006/07/12 14:18:13 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2006/07/12 14:18:13 | 000,009,535 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2006/07/12 14:18:13 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2005/08/12 17:57:09 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2004/09/26 19:32:38 | 000,044,706 | —- | C] () – C:\WINDOWS\System32\ZDMLu.INI
[2004/09/26 19:25:52 | 000,023,506 | —- | C] () – C:\WINDOWS\System32\ZDMLa.INI
[2004/08/10 14:28:20 | 000,001,088 | —- | C] () – C:\WINDOWS\System32\ZDWlan.INI
[2004/03/23 19:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2004/03/05 18:00:58 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2004/03/05 18:00:26 | 000,827,392 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2003/09/01 13:51:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\Installrt2500qa.dll
[2003/08/27 21:41:48 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/08/27 20:49:36 | 000,000,426 | —- | C] () – C:\WINDOWS\System32\Px.ini
[2003/08/27 20:47:54 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2003/08/27 20:47:53 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2003/08/27 20:47:53 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2003/08/27 20:47:53 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2003/08/27 20:47:53 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2003/08/27 20:47:53 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2003/08/27 20:25:44 | 000,000,000 | —- | C] () – C:\WINDOWS\CePMTray.INI
[2003/08/27 13:49:38 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/08/27 13:48:06 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/08/27 13:29:57 | 000,001,866 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/08/27 13:29:25 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/07/29 19:34:04 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\CeEKPolicy.dll
[2003/07/23 21:35:04 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\CeEPPolicy.dll
[2003/07/23 21:03:48 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\CeEPDefDat.dll
[2002/10/06 14:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 19:04:24 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/10/04 19:04:24 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 19:04:16 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/07/17 20:45:48 | 000,004,183 | —- | C] () – C:\WINDOWS\System32\drivers\TPIOMngr.sys
[1999/01/22 12:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2009/06/01 16:46:37 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Blender Foundation
[2009/09/06 22:40:24 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\FFSJ
[2010/06/11 18:04:46 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\FontCreator
[2009/04/02 23:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Graboid Inc
[2009/07/27 23:30:58 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\GrabPro
[2010/04/13 16:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\HAPedit
[2009/09/13 14:24:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\818\Application Data\ijjigame
[2003/08/27 20:53:21 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\InterTrust
[2006/07/12 14:25:44 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\InterVideo
[2008/07/20 21:34:56 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\MySQL
[2010/06/10 00:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Obsidium
[2008/11/24 01:27:54 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Opera
[2010/05/30 22:01:25 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Orbit
[2007/05/26 14:33:40 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\PlayFirst
[2008/07/17 14:56:06 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\postgresql
[2010/06/10 00:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Proxima Software
[2008/07/10 20:24:03 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Sony Setup
[2009/09/09 22:58:39 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Thinstall
[2008/12/07 19:53:37 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\TrueCrypt
[2007/12/30 12:53:32 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Uniblue
[2008/08/29 12:09:13 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Web Page Maker
[2009/02/23 20:28:55 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\WordWeb
[2007/05/11 00:53:17 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2007/12/31 13:20:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/10/20 18:42:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ijjigame
[2010/06/11 18:04:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MainType
[2006/09/21 19:13:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2007/05/26 14:33:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/04/19 13:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/07/12 14:21:22 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\Registration reminder 1.job
[2006/07/12 14:21:23 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\Registration reminder 3.job
[2010/06/13 01:58:00 | 000,000,242 | -H– | M] () – C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/06/13 02:11:00 | 000,000,274 | -H– | M] () – C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2002/08/29 08:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2002/08/29 08:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\I386\sp1.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002/08/29 04:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2002/08/29 08:00:00 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll
[2002/08/29 08:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2002/08/29 08:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2004/08/04 00:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2002/08/29 08:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2003/08/27 06:34:22 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2003/08/27 06:34:22 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2003/08/27 06:34:22 | 000,397,312 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /90 >
========== Files - Unicode (All) ==========
[2008/01/05 15:00:42 | 000,000,000 | —D | M](C:\Program Files\Common Files\M?crosoft) – C:\Program Files\Common Files\Mіcrosoft
[2007/12/24 12:06:47 | 000,000,000 | —D | M](C:\Program Files\Common Files\M?crosoft\M?crosoft) – C:\Program Files\Common Files\Mіcrosoft\Mіcrosoft
(C:\Program Files\Common Files\M?crosoft) – C:\Program Files\Common Files\Mіcrosoft
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:84098FD3
@Alternate Data Stream - 88 bytes -> C:\Auth.prof:SummaryInformation
@Alternate Data Stream - 498 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DD0CE449
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
Extras:
OTL Extras logfile created on: 6/13/2010 11:32:26 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\818\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
478.00 Mb Total Physical Memory | 228.00 Mb Available Physical Memory | 48.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 49.12 Gb Free Space | 65.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-TH3IEUQTQB
Current User Name: 818
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – C:\Program Files\Opera\opera.exe (Opera Software)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Disabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Disabled:Orbit – (Orbitdownloader.com)
"C:\WINDOWS\Downloaded Program Files\PurpleBean.exe" = C:\WINDOWS\Downloaded Program Files\PurpleBean.exe:*:Disabled:PurpleBean.exe – ()
"C:\Program Files\ijji\ijji REACTOR\REACTOR.exe" = C:\Program Files\ijji\ijji REACTOR\REACTOR.exe:*:Disabled:Reactor Application – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Disabled:Windows Live Call – (Microsoft Corporation)
"C:\Python31\pythonw.exe" = C:\Python31\pythonw.exe:*:Enabled:pythonw – ()
"C:\Program Files\Kaiba Corp VDS\KCVDS.exe" = C:\Program Files\Kaiba Corp VDS\KCVDS.exe:*:Enabled:KCVDS – (Kaiba Corp)
"C:\cygwin\bin\XWin.exe" = C:\cygwin\bin\XWin.exe:*:Enabled:XWin – ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{107C7E59-F4CF-444F-BCCC-8223137D1AD1}" = TouchPad On/Off Utility
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2AFDE05E-934B-4A3A-B6A8-809A7A654EF8}" = Toshiba Registration
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3ad61ee5-81d2-4d7e-adef-da1dd37277d1}" = Python 3.1
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}" = TOSHIBA Console
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{41DBA4F1-E295-41B3-9922-7B346C5B8EBF}" = TOSHIBA Hotkey Utility
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{49371ACC-929A-48BB-AA5E-A35FE3D0CA5F}" = WLAN
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{666CF041-77BE-414E-9A9D-0A227E9B48F8}" = Norton™ Security Scan
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8318FEFD-F467-44D6-82B8-129374BFE9B1}" = Opera 9.62
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek Fast Ethernet Adapter Driver
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B83DA26B-5237-41E8-8612-8F3F63F69811}" = TOSHIBA Power Management Utility
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{DDC146FA-73E0-4FA1-A353-841EA14BF600}" = Drag'n Drop CD+DVD
"{EC86822D-3A20-11D5-801B-00E029348F40}" = SMSC IrCC Driver V5.1.2462.0 (WinXP)
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agnitum Outpost Firewall 1.0" = Agnitum Outpost Firewall 1.0
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CANONBJ_Deinstall_CNMCP74.DLL" = Canon iP2200
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"GraphicsGale FreeEdition_is1" = GraphicsGale FreeEdition version 1.93.12
"Hamachi" = Hamachi 1.0.3.0
"InstallShield_{107C7E59-F4CF-444F-BCCC-8223137D1AD1}" = TouchPad On/Off Utility
"InstallShield_{41DBA4F1-E295-41B3-9922-7B346C5B8EBF}" = TOSHIBA Hotkey Utility
"InstallShield_{B83DA26B-5237-41E8-8612-8F3F63F69811}" = TOSHIBA Power Management Utility
"Kaiba Corp VDS_is1" = Kaiba Corp Virtual Duel System 1.16
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Orbit_is1" = Orbit Downloader
"RPG Maker 2003_is1" = RPG Maker 2003 v1.08
"RPG Maker VX RTP_is1" = RPG Maker VX RTP
"RPG Maker VX_is1" = RPG Maker VX
"SCAR 2.03_is1" = SCAR CDE 2.03
"Screen Recorder Gold" = Screen Recorder Gold
"SpriteForge_is1" = VE1.8-R1.9
"SpywareBlaster_is1" = SpywareBlaster v3.5.1
"SpywareGuard_is1" = SpywareGuard v2.2
"SystemRequirementsLab" = System Requirements Lab
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Toshiba Tbiosdrv Driver" = Toshiba Tbiosdrv Driver
"TrueCrypt" = TrueCrypt
"VLC media player" = VLC media player 0.9.9
"WampServer 2_is1" = WampServer 2.0
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WLAN 802.11g USB2.0 Utility" = WLAN 802.11g USB2.0 Utility
"WordWeb" = WordWeb
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/11/2010 5:11:22 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =
Error - 6/11/2010 6:11:21 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =
Error - 6/11/2010 6:26:36 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Application Hang | ID = 1002
Description = Hanging application SUPERAntiSpyware.exe, version 4.15.0.1000, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 6/11/2010 6:29:40 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Application Hang | ID = 1002
Description = Hanging application SUPERAntiSpyware.exe, version 4.15.0.1000, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 6/11/2010 7:11:20 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =
Error - 6/11/2010 7:36:38 PM | Computer Name = YOUR-TH3IEUQTQB | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 6/12/2010 9:11:06 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =
Error - 6/12/2010 10:11:06 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =
Error - 6/13/2010 1:11:07 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =
Error - 6/13/2010 2:11:05 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =
[ System Events ]
Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 6/11/2010 7:35:53 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2
Error - 6/12/2010 11:03:27 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2
Error - 6/12/2010 12:49:35 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2
Error - 6/12/2010 12:56:05 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2
Error - 6/12/2010 2:34:19 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2
Error - 6/13/2010 12:34:44 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2
< End of report >